[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 6 20:03:22 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c10038a3 by Moritz Muehlenhoff at 2026-09-06T21:03:10+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -956,7 +956,7 @@ CVE-2026-52763 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6,
CVE-2026-52762 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWi ...)
NOT-FOR-US: YesWiki
CVE-2026-52691 (** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Ele ...)
- TODO: check
+ NOT-FOR-US: Apache Griffin Hive Metastore Module
CVE-2026-50894 (easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with D ...)
NOT-FOR-US: easyadmin
CVE-2026-50553 (Note Mark is an open-source note-taking application. Prior to version ...)
@@ -36543,7 +36543,6 @@ CVE-2026-15816 (A flaw was found in dracut. The die() error-handling function wr
[trixie] - dracut <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459963
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500889
- TODO: check
CVE-2026-15570 (An improper restriction of URL schemes and destinations in the SmartCe ...)
NOT-FOR-US: Telefunken TE24553B45V2DZ Smart TV
CVE-2026-15239 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1 ...)
@@ -45686,7 +45685,7 @@ CVE-2026-12124 (The PDFDraft \u2013 Drag & Drop PDF Builder, PDF Viewer, Embed &
CVE-2026-12001 (A hardcoded credential vulnerability exists in the firmware of multipl ...)
NOT-FOR-US: TPLink
CVE-2025-63913 (An issue was discovered in OpenSBI 1.3 allowing attackers to cause a d ...)
- TODO: check
+ NOT-FOR-US: OpenSBI
CVE-2026-64555 (In the Linux kernel, the following vulnerability has been resolved: K ...)
{DSA-6405-1 DLA-4724-1}
- linux 7.1.5-1
@@ -46417,7 +46416,6 @@ CVE-2026-16566
[bookworm] - ansible <not-affected> (Vulnerable code not present)
[bullseye] - ansible <not-affected> (Vulnerable code not present)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506113
- TODO: check upstream report and status on fix
CVE-2026-14957 (In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_Extra ...)
- libreswan 5.2-2.5 (bug #1143067)
[trixie] - libreswan <no-dsa> (Minor issue; can be fixed via point release)
@@ -71899,20 +71897,16 @@ CVE-2026-13504 (A vulnerability has been found in code-projects Project Manageme
CVE-2026-13503 (A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by ...)
- antlr4 <undetermined>
NOTE: https://github.com/wooyun123/wooyun/issues/8
- TODO: check upstream reporting and status
CVE-2026-13502 (A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the f ...)
- antlr4 <undetermined>
NOTE: https://github.com/wooyun123/wooyun/issues/7
- TODO: check upstream reporting and status
CVE-2026-13501 (A security vulnerability has been detected in antlr ANTLR4 up to 4.13. ...)
- antlr4 <undetermined>
NOTE: https://github.com/wooyun123/wooyun/issues/6
- TODO: check upstream reporting and status
CVE-2026-13500 (A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected ...)
- antlr4 <undetermined>
NOTE: https://github.com/wooyun123/wooyun/issues/4
NOTE: https://github.com/antlr/antlr4/issues/4952
- TODO: check upstream reporting and status
CVE-2026-13499 (A security flaw has been discovered in yashpokharna2555 restaurent-man ...)
NOT-FOR-US: yashpokharna2555 restaurent-management-system
CVE-2026-13498 (A vulnerability was identified in yashpokharna2555 restaurent-manageme ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c10038a34755ada3052af4860ff1e882b1742ea5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c10038a34755ada3052af4860ff1e882b1742ea5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/aa6bde41/attachment.htm>
More information about the debian-security-tracker-commits
mailing list